Every registered service has policies. Far fewer have a policy library that works: one where staff know which document to reach for, the content describes the service they actually work in, and the versions in the folder are the versions in use. The difference shows up at the worst moments, when a safeguarding concern lands or an assessor asks a support worker how a procedure works.

Here is how to build a library that earns its keep.

Why policy libraries fail

  • Too many documents. Two hundred policies bought as a job lot, most never opened, guarantee that nobody reads any of them.
  • Generic content. Policies that mention nursing procedures in a supported living service, or another provider's name left in from the template, tell everyone that the library is decoration.
  • No connection to practice. If induction, supervision and audits never reference the policies, the library exists in parallel to the service rather than inside it.
  • No version control. Three copies of the medication policy in circulation is worse than one imperfect copy, because nobody knows which one counts.

Start from your service, not a template list

The right set of policies follows from your registration: your regulated activities, your service type and the people you support. A domiciliary care agency needs lone working and travel between calls covered properly; a residential service needs the premises and environment covered; a service supporting people who may lack capacity needs consent and best-interests decision-making handled in depth, not in passing.

Write down what your service actually does, then build the list from that. It is also what CQC expects: your policies are part of the evidence that you can meet the regulations for the activities you are registered to carry on, and they should agree with your statement of purpose. If you are pre-registration, our registration checklist shows where policies fit in the wider application.

The core set most services need

Lists vary by service type, but a working core usually includes:

  • safeguarding adults (and children, where relevant);
  • medication management;
  • consent, mental capacity and best-interests decision-making;
  • complaints, and compliments and feedback;
  • infection prevention and control;
  • health and safety, including risk assessment and lone working where relevant;
  • safe recruitment, induction, training and supervision;
  • duty of candour and incident management;
  • whistleblowing;
  • data protection, confidentiality and record keeping;
  • equality, diversity and human rights;
  • business continuity.

Treat that as a starting point to tailor, not a finish line to laminate.

Make each policy usable

  • Plain language. A policy is an instruction to a busy colleague, not a legal essay. Short sentences, active voice, no unexplained jargon.
  • Name the roles. "The registered manager will" and "support workers must" beat "the organisation shall ensure".
  • Separate policy from procedure. The policy states the commitment and the rules; the procedure is the step-by-step. Staff mostly need the procedure.
  • One page that matters. A summary box at the top covering what to do and who to contact will be read a hundred times more often than page nine.
  • Consistent housekeeping. Every document carries a version number, an owner, an issue date and a review date.

A word about "CQC-approved" policies

Be wary of anyone who claims their policies are CQC approved. CQC does not approve, endorse or accredit policies from any supplier, and assessors are unimpressed by branding that suggests otherwise. What CQC actually looks for is whether your policies reflect current legislation and guidance, match your service and are followed in practice. That is the standard our CQC policy packs are written to, tailored to each service rather than sold as a generic bundle, and if you need companion documents such as a statement of purpose or service-specific additions, our add-on services cover those.

Connect the library to daily practice

A policy only exists when someone behaves differently because of it. Wire the library into the routines you already run:

  • induction assigns the handful of policies each role genuinely needs, and checks understanding rather than collecting signatures;
  • supervision and team meetings take one policy topic at a time, using real scenarios;
  • audits check practice against the policy, and incidents trigger a check of whether the policy helped or hindered;
  • under CQC's current framework your processes are a named evidence category, so the link between document and practice is exactly what assessors probe. Our guide to the Single Assessment Framework explains how that evidence is weighed.

Keep it alive

Set a rolling review cycle so a manageable number of policies are reviewed each month, rather than facing all of them every year. Reissue documents when legislation, national guidance or your own incidents show a gap, not just when the review date arrives. Retire old versions visibly, keep an archive, and maintain one master index that says what is current. Ten minutes of librarianship a week keeps the whole system honest.

Where to start

Pick your three highest-risk policies, usually safeguarding, medication and consent, and test them against one question: would a new starter know what to do from this document alone? Fix those first and momentum follows. If you would rather start from a tailored, current library instead of repairing a generic one, book a free readiness call and we'll scope what your service actually needs.